CVE-2024-31408: Aiphone Co., Ltd Ix-BA

High severity, CVSS 8.0. EPSS: 1.1% chance of exploitation in the next 30 days.

OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker may execute an arbitrary OS command with root privileges by sending a specially crafted request.

Affected products

Published 2024-11-22. Last modified 2026-06-17.